logo

Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR

ID: 87c1bb46-9350-5b45-84a8-11ed4243a55f

STIX ID: report--87c1bb46-9350-5b45-84a8-11ed4243a55f

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Do Son

...
...

Cruciferra’s malware loader (selling Remus stealer) is being delivered in late-July 2026 ClickFix campaigns via ErrTraffic-injected JavaScript on compromised WordPress sites; attackers use clipboard PowerShell lures to sideload a DLL, perform process hollowing into signed binaries, and optionally deploy a signed-but-vulnerable driver (DCRCVDrv.sys) to kill ~145 AV/EDR processes from kernel space, while C2 domains are resolved via blockchain smart contracts (EtherHiding).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.